|
Log-Analyse und Auswertung: Programme beenden mit ErrorWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
24.09.2010, 09:19 | #1 | |
| Programme beenden mit Error Hallo, Alle Programme einschließlich des Notepads beenden mit einer Fehlermeldung. Das Problem scheint das gleiche wie in diesem Thread: http://www.trojaner-board.de/90696-a...blem-fest.html zu sein aber da MalewareBytes und OTL auf meinem PC andere Logs erzeugen weiß ich nicht wie ich die dort diskutierte Lösung anwenden soll. Reinigungsversuche mit AVIRA sind fehlgeschlagen (Trojaner wurden zwar gefunden und gelöscht aber das hat das Problem nicht gelöst) und ich habe den befallenen Rechner jetzt erstmal vom Internet abgeklemmt. Ich wäre sehr dankbar wenn jemand helfen könnte, hier sind die logs von MaleWareBytes und OTL gemacht mit den Einstellungen die im oben genannten Thread geraten werden: MaleWare: Zitat:
OTL Logfile: Code:
ATTFilter OTL logfile created on: 24.09.2010 09:45:54 - Run 1 OTL by OldTimer - Version 3.2.14.1 Folder = C:\Dokumente und Einstellungen\HansJurg\Desktop Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 71,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 83,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 465,75 Gb Total Space | 375,91 Gb Free Space | 80,71% Space Free | Partition Type: NTFS D: Drive not present or media not loaded Drive E: | 465,76 Gb Total Space | 333,49 Gb Free Space | 71,60% Space Free | Partition Type: NTFS Drive F: | 931,51 Gb Total Space | 379,19 Gb Free Space | 40,71% Space Free | Partition Type: NTFS G: Drive not present or media not loaded Drive H: | 1014,88 Mb Total Space | 42,39 Mb Free Space | 4,18% Space Free | Partition Type: FAT32 I: Drive not present or media not loaded Computer Name: CHOCHMAH Current User Name: HansJurg Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Dokumente und Einstellungen\HansJurg\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Programme\Java\jreN\bin\jqs.exe (Sun Microsystems, Inc.) PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - c:\Programme\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - c:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation) PRC - c:\Programme\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\Programme\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe () PRC - C:\Programme\avmwlanstick\WLanGUI.exe (AVM Berlin) PRC - C:\Programme\avmwlanstick\WLanNetService.exe (AVM Berlin) PRC - C:\Programme\Alarm\Alarm.exe (Bluefive software) PRC - C:\Programme\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation) PRC - C:\Programme\Microsoft ActiveSync\rapimgr.exe (Microsoft Corporation) PRC - C:\WINDOWS\system32\CmWatch.exe () ========== Modules (SafeList) ========== MOD - C:\Dokumente und Einstellungen\HansJurg\Desktop\OTL.exe (OldTimer Tools) MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll (Microsoft Corporation) MOD - C:\WINDOWS\system32\shfolder.dll (Microsoft Corporation) MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (nHancer) -- C:\Programme\nHancer\nHancerService.exe File not found SRV - (HPWJAService) -- C:\Programme\Hewlett-Packard\Web Jetadmin 10\bin\HPWJAService.exe File not found SRV - (AppMgmt) -- C:\WINDOWS\System32\appmgmts.dll File not found SRV - (JavaQuickStarterService) -- C:\Programme\Java\jreN\bin\jqs.exe (Sun Microsystems, Inc.) SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) -- C:\Programme\WinPcap\rpcapd.exe (CACE Technologies, Inc.) SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (HPWJAUpdateService) -- C:\Programme\Gemeinsame Dateien\Hewlett-Packard\WJA Update Service\HPWJAUpdateService.exe () SRV - (MSSQL$HPWJA) SQL Server (HPWJA) -- c:\Programme\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (SQLWriter) -- c:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation) SRV - (SQLBrowser) -- c:\Programme\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) SRV - (MSSQLServerADHelper) -- c:\Programme\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation) SRV - (odserv) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation) SRV - (LG SCSI Commander) -- C:\WINDOWS\system32\LGAutorunService.exe () SRV - (MySQL) -- C:\Programme\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe () SRV - (AVM WLAN Connection Service) -- C:\Programme\avmwlanstick\WLanNetService.exe (AVM Berlin) SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation) SRV - (IDriverT) -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation) ========== Driver Services (SafeList) ========== DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys File not found DRV - (MEMSWEEP2) -- C:\WINDOWS\System32\357.tmp File not found DRV - (MagicTune) -- C:\WINDOWS\System32\drivers\MTiCtwl.sys File not found DRV - (HLPSYS) -- C:\WINDOWS\System32\drivers\hlp.sys File not found DRV - (gtermddo) -- C:\DOKUME~1\PETERH~1\LOKALE~1\Temp\gtermddo.sys File not found DRV - (cpuz130) -- C:\DOKUME~1\PETERH~1\LOKALE~1\Temp\cpuz130\cpuz_x32.sys File not found DRV - (AIDA32Driver) -- C:\Dokumente und Einstellungen\HansJurg\Desktop\bench\aida32.sys File not found DRV - (SAVRKBootTasks) -- C:\WINDOWS\system32\SAVRKBootTasks.sys (Sophos Plc) DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH) DRV - (NPF) -- C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.) DRV - (USBModem) -- C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.) DRV - (UsbDiag) -- C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.) DRV - (usbbus) -- C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.) DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH) DRV - (NuidFltr) -- C:\WINDOWS\system32\drivers\nuidfltr.sys (Microsoft Corporation) DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH) DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH) DRV - (bfturboh) -- C:\WINDOWS\system32\drivers\bfturboh.sys (BUFFALO INC.) DRV - (MPE) -- C:\WINDOWS\system32\drivers\MPE.sys (Microsoft Corporation) DRV - (NwlnkIpx) -- C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation) DRV - (nm) -- C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation) DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows (R) Server 2003 DDK provider) DRV - (atksgt) -- C:\WINDOWS\system32\drivers\atksgt.sys () DRV - (lirsgt) -- C:\WINDOWS\system32\drivers\lirsgt.sys () DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation) DRV - (mod7700) -- C:\WINDOWS\system32\drivers\mod7700.sys (DiBcom SA) DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.) DRV - (AtcL001) -- C:\WINDOWS\system32\drivers\atl01_xp.sys (Attansic Technology corporation.) DRV - (FWLANUSB) -- C:\WINDOWS\system32\drivers\fwlanusb.sys (AVM GmbH) DRV - (avmeject) -- C:\WINDOWS\system32\drivers\avmeject.sys (AVM Berlin) DRV - (BUFADPT) -- C:\WINDOWS\system32\BUFADPT.SYS (BUFFALO INC.) DRV - (MTsensor) -- C:\WINDOWS\system32\drivers\ASACPI.sys () DRV - (NwlnkNb) -- C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation) DRV - (NwlnkSpx) -- C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation) DRV - (UMSSSTOR) -- C:\WINDOWS\system32\drivers\Umss.SYS (C-Media Corporation) DRV - (WmXlCore) -- C:\WINDOWS\system32\drivers\WmXlCore.sys (Logitech Inc.) DRV - (WmFilter) -- C:\WINDOWS\system32\drivers\WmFilter.sys (Logitech Inc.) DRV - (WmBEnum) -- C:\WINDOWS\system32\drivers\WmBEnum.sys (Logitech Inc.) DRV - (WmVirHid) -- C:\WINDOWS\system32\drivers\WmVirHid.sys (Logitech Inc.) DRV - (Stltrk2k) -- C:\WINDOWS\System32\drivers\Stltrk2k.sys (SCM Microsystems Inc.) DRV - (UPATC) -- C:\WINDOWS\system32\drivers\upatc.sys (SCM Microsystems Inc.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Google" FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?sourceid=navclient&hl=de&q=" FF - prefs.js..network.proxy.type: 0 FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Programme\Java\jreN\lib\deploy\jqs\ff [2010.01.14 17:58:48 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Programme\Mozilla Firefox\components [2010.08.17 07:12:54 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2010.08.24 17:57:36 | 000,000,000 | ---D | M] [2009.09.13 17:03:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\HansJurg\Anwendungsdaten\Mozilla\Extensions [2010.09.17 14:29:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\HansJurg\Anwendungsdaten\Mozilla\Firefox\Profiles\sbr103vo.default\extensions [2010.08.08 19:42:56 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Dokumente und Einstellungen\HansJurg\Anwendungsdaten\Mozilla\Firefox\Profiles\sbr103vo.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010.08.08 10:12:12 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Dokumente und Einstellungen\HansJurg\Anwendungsdaten\Mozilla\Firefox\Profiles\sbr103vo.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2010.08.07 19:21:09 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions [2010.07.12 18:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npwachk.dll [2010.07.23 02:48:56 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml [2010.07.23 02:48:56 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml [2010.07.23 02:48:56 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml [2010.07.23 02:48:56 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml [2010.07.23 02:48:56 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.07.24 12:06:44 | 000,001,075 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 www.spiegel.de O1 - Hosts: 127.0.0.1 www.focus.de O1 - Hosts: 127.0.0.1 www.stern.de O1 - Hosts: 127.0.0.1 www.bild.de O1 - Hosts: 127.0.0.1 www.wwtdd.com O1 - Hosts: 127.0.0.1 www.tmz.com O1 - Hosts: 127.0.0.1 www.bild.de O1 - Hosts: 127.0.0.1 hxxp://www.thesun.co.uk/ O1 - Hosts: 127.0.0.1 hxxp://www.timeslive.co.za/ O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jreN\bin\jp2ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jreN\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {BD0E4D83-654E-4213-965B-FCBE887061F4} - No CLSID value found. O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [AVMWlanClient] C:\Programme\avmwlanstick\WLanGUI.exe (AVM Berlin) O4 - HKLM..\Run: [CmCardRun] C:\WINDOWS\system32\CmWatch.exe () O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe () O4 - HKCU..\Run: [Cgesivuluye] C:\WINDOWS\arant40.DLL File not found O4 - HKCU..\Run: [H/PC Connection Agent] C:\Programme\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation) O4 - HKCU..\Run: [Reskbd] C:\Dokumente und Einstellungen\HansJurg\Anwendungsdaten\Adobe\Update\bltgdi.exe () O4 - Startup: C:\Dokumente und Einstellungen\HansJurg\Startmenü\Programme\Autostart\Dropbox.lnk = C:\Dokumente und Einstellungen\HansJurg\Anwendungsdaten\Dropbox\bin\Dropbox.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 355 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.) O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programme\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Mobilen Favoriten erstellen... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programme\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation) O15 - HKLM\..Trusted Domains: hp.com ([]http in Vertrauenswürdige Sites) O15 - HKLM\..Trusted Domains: hp.com ([]https in Vertrauenswürdige Sites) O16 - DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab (F-Secure Online Scanner Launcher) O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab (System Requirements Lab Class) O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class) O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} hxxp://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object) O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} hxxp://simcity.ea.com/update/EARTPX.cab (EARTPatchX Class) O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab (Reg Error: Key error.) O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab (NVIDIA Smart Scan) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19) O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} hxxp://simcity.ea.com/update/MaxisSimCity4PatcherX.cab (MaxisSimCity4PatcherX Control) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19) O18 - Protocol\Handler\hppfile {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Programme\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll (Hewlett-Packard Company) O18 - Protocol\Handler\hppsam {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Programme\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll (Hewlett-Packard Company) O18 - Protocol\Handler\hppzip {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Programme\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll (Hewlett-Packard Company) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O24 - Desktop Components:1 () - hxxp://www.spiegel.de/ O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\HansJurg\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\HansJurg\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{0f8cd3e9-ec0c-11de-b084-001a4f9d2a1d}\Shell - "" = AutoRun O33 - MountPoints2\{0f8cd3e9-ec0c-11de-b084-001a4f9d2a1d}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{0f8cd3e9-ec0c-11de-b084-001a4f9d2a1d}\Shell\AutoRun\command - "" = F:\Windows\CHECK\DriveNavigator.exe -- File not found O33 - MountPoints2\{592bada5-625b-11df-b0c2-001a4f9d2a1d}\Shell - "" = AutoRun O33 - MountPoints2\{592bada5-625b-11df-b0c2-001a4f9d2a1d}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{592bada5-625b-11df-b0c2-001a4f9d2a1d}\Shell\AutoRun\command - "" = H:\Windows\CHECK\DriveNavigator.exe -- File not found O33 - MountPoints2\J\Shell - "" = AutoRun O33 - MountPoints2\J\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\Windows\CHECK\DriveNavigator.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010.09.24 09:45:32 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\HansJurg\Desktop\OTL.exe [2010.09.24 01:02:22 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\HansJurg\Desktop\Meersburg Schreiber [2010.09.24 00:58:32 | 000,018,816 | ---- | C] (Sophos Plc) -- C:\WINDOWS\System32\SAVRKBootTasks.sys [2010.09.24 00:06:19 | 000,000,000 | ---D | C] -- C:\Programme\Sophos [2010.09.23 22:19:07 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\HansJurg\Desktop\antivir_rootkit [2010.09.23 22:18:56 | 000,367,616 | ---- | C] (Avira GmbH) -- C:\Dokumente und Einstellungen\HansJurg\Desktop\removaltool-win32-de18.exe [2010.09.23 22:17:56 | 003,313,664 | ---- | C] (Avira GmbH) -- C:\Dokumente und Einstellungen\HansJurg\Desktop\bootwizard.exe [2010.09.23 22:13:33 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\Macromedia [2010.09.23 22:03:42 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\Adobe [2010.09.23 19:12:03 | 000,000,000 | R--D | C] -- C:\32788R22FWJFW [2010.09.23 16:16:02 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW.1.tmp [2010.09.23 16:08:49 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW.0.tmp [2010.09.23 15:32:34 | 000,678,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\67092805 [2010.09.22 23:58:48 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\HansJurg\Anwendungsdaten\Helper [2010.09.19 23:42:41 | 000,167,936 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrszht.dll [2010.09.19 23:42:41 | 000,126,976 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrszht.dll [2010.09.19 23:42:40 | 000,303,104 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrstr.dll [2010.09.19 23:42:40 | 000,258,048 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrstr.dll [2010.09.19 23:42:40 | 000,225,280 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrszhc.dll [2010.09.19 23:42:40 | 000,163,840 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrszhc.dll [2010.09.19 23:42:39 | 000,290,816 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrsth.dll [2010.09.19 23:42:39 | 000,253,952 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrsth.dll [2010.09.19 23:42:38 | 000,294,912 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrssv.dll [2010.09.19 23:42:38 | 000,253,952 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrssv.dll [2010.09.19 23:42:37 | 000,303,104 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrssl.dll [2010.09.19 23:42:37 | 000,299,008 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrssk.dll [2010.09.19 23:42:37 | 000,258,048 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrssl.dll [2010.09.19 23:42:37 | 000,258,048 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrssk.dll [2010.09.19 23:42:36 | 000,315,392 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrsru.dll [2010.09.19 23:42:36 | 000,270,336 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrsru.dll [2010.09.19 23:42:35 | 000,323,584 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrspt.dll [2010.09.19 23:42:35 | 000,319,488 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrsptb.dll [2010.09.19 23:42:35 | 000,274,432 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrspt.dll [2010.09.19 23:42:35 | 000,266,240 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrsptb.dll [2010.09.19 23:42:34 | 000,294,912 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrspl.dll [2010.09.19 23:42:34 | 000,253,952 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrspl.dll [2010.09.19 23:42:33 | 000,319,488 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrsnl.dll [2010.09.19 23:42:33 | 000,299,008 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrsno.dll [2010.09.19 23:42:33 | 000,274,432 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrsnl.dll [2010.09.19 23:42:33 | 000,253,952 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrsno.dll [2010.09.19 23:42:32 | 000,258,048 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrsko.dll [2010.09.19 23:42:32 | 000,196,608 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrsko.dll [2010.09.19 23:42:31 | 000,323,584 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrsit.dll [2010.09.19 23:42:31 | 000,278,528 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrsit.dll [2010.09.19 23:42:31 | 000,266,240 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrsja.dll [2010.09.19 23:42:31 | 000,212,992 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrsja.dll [2010.09.19 23:42:30 | 000,315,392 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrshu.dll [2010.09.19 23:42:30 | 000,258,048 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrshu.dll [2010.09.19 23:42:29 | 000,327,680 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrshe.dll [2010.09.19 23:42:29 | 000,278,528 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrshe.dll [2010.09.19 23:42:28 | 000,327,680 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrsfr.dll [2010.09.19 23:42:28 | 000,303,104 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrsfi.dll [2010.09.19 23:42:28 | 000,282,624 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrsfr.dll [2010.09.19 23:42:27 | 000,327,680 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrsesm.dll [2010.09.19 23:42:27 | 000,274,432 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrsesm.dll [2010.09.19 23:42:27 | 000,249,856 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrsfi.dll [2010.09.19 23:42:26 | 000,335,872 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrses.dll [2010.09.19 23:42:26 | 000,335,872 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrsel.dll [2010.09.19 23:42:26 | 000,286,720 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrseng.dll [2010.09.19 23:42:26 | 000,282,624 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrses.dll [2010.09.19 23:42:26 | 000,282,624 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrsel.dll [2010.09.19 23:42:26 | 000,245,760 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrseng.dll [2010.09.19 23:42:25 | 000,311,296 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrsde.dll [2010.09.19 23:42:25 | 000,278,528 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrsde.dll [2010.09.19 23:42:24 | 000,294,912 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrsda.dll [2010.09.19 23:42:24 | 000,286,720 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrscs.dll [2010.09.19 23:42:24 | 000,282,624 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwrsar.dll [2010.09.19 23:42:24 | 000,253,952 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrsda.dll [2010.09.19 23:42:24 | 000,249,856 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrscs.dll [2010.09.19 23:42:23 | 001,073,152 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcpluir.dll [2010.09.19 23:42:23 | 000,753,664 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcplui.exe [2010.09.19 23:42:23 | 000,327,680 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvrsar.dll [2010.09.19 23:42:23 | 000,307,200 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvexpbar.dll [2010.09.19 23:42:22 | 000,413,696 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcpl.cpl [2010.09.19 23:42:22 | 000,045,056 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvmccsrs.dll [2010.09.19 23:42:21 | 000,147,456 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcolor.exe [2010.09.19 23:42:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\nview [2010.09.19 23:37:47 | 002,519,040 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwssr.dll [2010.09.19 23:37:46 | 002,498,560 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwss.dll [2010.09.19 23:37:44 | 003,715,072 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvvitvsr.dll [2010.09.19 23:37:44 | 003,710,976 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvvitvs.dll [2010.09.19 23:37:44 | 000,081,920 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwddi.dll [2010.09.19 23:37:41 | 006,901,760 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvoglnt.dll [2010.09.19 23:37:41 | 002,854,912 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvmoblsr.dll [2010.09.19 23:37:41 | 001,228,800 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvmobls.dll [2010.09.19 23:37:41 | 000,458,752 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvmccssr.dll [2010.09.19 23:37:41 | 000,229,376 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvmccs.dll [2010.09.19 23:37:41 | 000,188,416 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvmccss.dll [2010.09.19 23:37:41 | 000,081,920 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvmctray.dll [2010.09.19 23:37:39 | 003,334,144 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvgamesr.dll [2010.09.19 23:37:38 | 006,549,504 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvdisps.dll [2010.09.19 23:37:38 | 005,611,520 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvdispsr.dll [2010.09.19 23:37:38 | 003,420,160 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvgames.dll [2010.09.19 23:37:36 | 008,523,776 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcpl.dll [2010.09.19 23:37:36 | 000,385,024 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvapi.dll [2010.09.19 23:37:36 | 000,035,328 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcodins.dll [2010.09.19 23:37:36 | 000,035,328 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcod.dll [2010.09.19 23:37:19 | 000,000,000 | ---D | C] -- C:\Programme\Nvidia Omega Drivers [2010.09.17 19:35:29 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\HansJurg\Desktop\174CANON [2010.09.13 17:44:40 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\HansJurg\Desktop\80tage [2010.09.10 21:45:37 | 000,061,440 | ---- | C] (Windswept Software - hxxp://windsweptsoftware.com) -- C:\WINDOWS\System32\digitbox.ocx [2010.09.10 21:45:37 | 000,000,000 | ---D | C] -- C:\Programme\Alarm [2010.09.07 21:45:35 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\HansJurg\Eigene Dateien\StarCraft II [2010.09.07 21:45:35 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\Blizzard Entertainment [2010.09.07 21:45:35 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Blizzard Entertainment [2010.09.07 19:20:42 | 000,000,000 | ---D | C] -- C:\Programme\7-Zip [2010.08.30 14:51:30 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\HansJurg\Anwendungsdaten\UltraVNC [2010.08.30 14:29:16 | 000,000,000 | ---D | C] -- C:\Programme\UltraVNC [2010.01.04 20:18:06 | 001,008,128 | ---- | C] (GnuWin32 <hxxp://gnuwin32.sourceforge.net>) -- C:\Programme\libiconv2.dll [2010.01.04 20:18:06 | 000,140,288 | ---- | C] (GnuWin32 <hxxp://gnuwin32.sourceforge.net>) -- C:\Programme\pcre3.dll [2010.01.04 20:18:06 | 000,103,424 | ---- | C] (GNU <www.gnu.org>) -- C:\Programme\libintl3.dll [2010.01.04 20:18:06 | 000,096,256 | ---- | C] (GnuWin32 <hxxp://gnuwin32.sourceforge.net>) -- C:\Programme\grep.exe [2010.01.04 20:18:06 | 000,092,160 | ---- | C] (GnuWin32 <hxxp://gnuwin32.sourceforge.net>) -- C:\Programme\egrep.exe [2010.01.04 20:18:06 | 000,079,360 | ---- | C] (GnuWin32 <hxxp://gnuwin32.sourceforge.net>) -- C:\Programme\regex2.dll [2010.01.04 20:18:06 | 000,054,784 | ---- | C] (GnuWin32 <hxxp://gnuwin32.sourceforge.net>) -- C:\Programme\fgrep.exe [2008.01.27 12:51:25 | 000,467,456 | ---- | C] ( ) -- C:\WINDOWS\pano12.dll [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [46 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [2 C:\*.tmp files -> C:\*.tmp -> ] [10 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010.09.24 09:30:05 | 000,001,088 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2010.09.24 09:10:20 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\HansJurg\Desktop\OTL.exe [2010.09.24 09:09:21 | 000,000,184 | ---- | M] () -- C:\WINDOWS\hpbafd.ini [2010.09.24 07:00:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\{10B0D67B-D9BC-47EB-B65F-5580D9C88CDB}_CHOCHMAH_HansJurg.job [2010.09.24 01:00:17 | 000,001,084 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2010.09.24 01:00:13 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2010.09.24 01:00:11 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010.09.24 00:59:02 | 017,563,648 | ---- | M] () -- C:\Dokumente und Einstellungen\HansJurg\ntuser.dat [2010.09.24 00:59:02 | 000,000,300 | -HS- | M] () -- C:\Dokumente und Einstellungen\HansJurg\ntuser.ini [2010.09.24 00:58:46 | 005,320,194 | -H-- | M] () -- C:\Dokumente und Einstellungen\HansJurg\Lokale Einstellungen\Anwendungsdaten\IconCache.db [2010.09.24 00:06:10 | 001,376,832 | ---- | M] () -- C:\Dokumente und Einstellungen\HansJurg\Desktop\sar_15_sfx.exe [2010.09.23 22:18:56 | 000,367,616 | ---- | M] (Avira GmbH) -- C:\Dokumente und Einstellungen\HansJurg\Desktop\removaltool-win32-de18.exe [2010.09.23 22:18:08 | 003,313,664 | ---- | M] (Avira GmbH) -- C:\Dokumente und Einstellungen\HansJurg\Desktop\bootwizard.exe [2010.09.23 22:18:01 | 000,065,893 | ---- | M] () -- C:\Dokumente und Einstellungen\HansJurg\Desktop\antivir_rootkit.zip [2010.09.23 19:09:35 | 000,001,374 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010.09.23 19:09:29 | 000,415,856 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2010.09.23 16:08:48 | 003,850,457 | ---- | M] () -- C:\Dokumente und Einstellungen\HansJurg\Desktop\cofi.exe [2010.09.23 16:00:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\{C57B008A-D395-4917-9F6E-A43D765C49DD}_CHOCHMAH_HansJurg.job [2010.09.23 10:00:00 | 000,000,402 | -H-- | M] () -- C:\WINDOWS\tasks\{D85BF3CA-9CDC-4B5B-8A61-07086F74D74A}_CHOCHMAH_HansJurg.job [2010.09.22 02:56:37 | 000,087,040 | ---- | M] () -- C:\Dokumente und Einstellungen\HansJurg\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.09.21 20:08:21 | 000,123,791 | ---- | M] () -- C:\Dokumente und Einstellungen\HansJurg\Eigene Dateien\The.Godfather.Trilogy.720p.BluRay.x264-HD.4468721.TPB.torrent [2010.09.21 14:47:04 | 000,164,081 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml [2010.09.21 07:07:00 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job [2010.09.20 19:43:11 | 004,414,842 | ---- | M] () -- C:\Dokumente und Einstellungen\HansJurg\Desktop\Leopard 3a5dk Afghanistan.skp [2010.09.20 19:18:59 | 003,944,030 | ---- | M] () -- C:\Dokumente und Einstellungen\HansJurg\Desktop\tank_tracks.skp [2010.09.20 09:56:29 | 000,000,249 | ---- | M] () -- C:\WINDOWS\emug3.ini [2010.09.19 23:37:19 | 000,472,576 | ---- | M] () -- C:\WINDOWS\Nvidia Omega Drivers v2.169.21 Uninstall.exe [2010.09.19 17:44:25 | 012,731,712 | ---- | M] () -- C:\Dokumente und Einstellungen\HansJurg\Eigene Dateien\0548456956.wmv [2010.09.19 13:00:08 | 009,531,217 | ---- | M] () -- C:\Dokumente und Einstellungen\HansJurg\Desktop\Sounds of Rain and Thunder on the River.mp3 [2010.09.18 15:55:16 | 000,000,009 | ---- | M] () -- C:\WINDOWS\System32\WIN.INI [2010.09.18 15:55:16 | 000,000,009 | ---- | M] () -- C:\WINDOWS\System32\SYSTEM.INI [2010.09.18 15:55:16 | 000,000,009 | ---- | M] () -- C:\WINDOWS\System32\PROTOCOL.INI [2010.09.17 19:37:10 | 000,002,962 | ---- | M] () -- C:\Dokumente und Einstellungen\HansJurg\.ufrawrc [2010.09.17 11:01:52 | 001,182,206 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2010.09.17 11:01:52 | 000,499,200 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat [2010.09.17 11:01:52 | 000,482,286 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2010.09.17 11:01:52 | 000,098,642 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat [2010.09.17 11:01:52 | 000,085,816 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2010.09.15 07:15:59 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2010.09.15 01:48:05 | 041,137,112 | ---- | M] () -- C:\Dokumente und Einstellungen\HansJurg\Eigene Dateien\3096964192.wmv [2010.09.15 01:35:37 | 051,761,276 | ---- | M] () -- C:\Dokumente und Einstellungen\HansJurg\Eigene Dateien\6032963601.wmv [2010.09.13 17:48:17 | 000,130,233 | ---- | M] () -- C:\Dokumente und Einstellungen\HansJurg\.recently-used.xbel [2010.09.13 15:16:27 | 000,139,336 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2010.09.13 15:16:06 | 000,214,720 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.xtr [2010.09.13 13:29:17 | 000,043,520 | ---- | M] () -- C:\WINDOWS\System32\CmdLineExt03.dll [2010.09.13 12:01:45 | 000,000,821 | ---- | M] () -- C:\Dokumente und Einstellungen\HansJurg\Desktop\Britannica.lnk [2010.09.13 10:03:07 | 000,232,968 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb0.bin [2010.09.13 10:03:07 | 000,000,001 | ---- | M] () -- C:\WINDOWS\System32\nvdrssel.bin [2010.09.13 10:03:05 | 000,232,968 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb1.bin [2010.09.13 10:03:05 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvdrswr.lk [2010.09.10 21:45:37 | 000,000,572 | ---- | M] () -- C:\Dokumente und Einstellungen\HansJurg\Desktop\Alarm.lnk [2010.09.07 20:28:29 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat [2010.09.04 11:07:14 | 1295,733,145 | ---- | M] () -- C:\Dokumente und Einstellungen\HansJurg\Eigene Dateien\ddn.rar [2010.08.27 13:36:38 | 000,000,085 | ---- | M] () -- C:\WINDOWS\RealFlight.INI [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [46 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [2 C:\*.tmp files -> C:\*.tmp -> ] [10 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ] ========== Files Created - No Company Name ========== [2010.09.24 00:06:08 | 001,376,832 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Desktop\sar_15_sfx.exe [2010.09.23 22:18:01 | 000,065,893 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Desktop\antivir_rootkit.zip [2010.09.23 16:08:15 | 003,850,457 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Desktop\cofi.exe [2010.09.21 20:08:21 | 000,123,791 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Eigene Dateien\The.Godfather.Trilogy.720p.BluRay.x264-HD.4468721.TPB.torrent [2010.09.21 14:47:00 | 000,159,458 | ---- | C] () -- C:\WINDOWS\System32\nvapps.nvb [2010.09.20 19:42:56 | 004,414,842 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Desktop\Leopard 3a5dk Afghanistan.skp [2010.09.20 19:18:43 | 003,944,030 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Desktop\tank_tracks.skp [2010.09.19 23:42:42 | 000,164,081 | ---- | C] () -- C:\WINDOWS\System32\nvapps.xml [2010.09.19 23:42:22 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll [2010.09.19 23:42:22 | 001,626,112 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe [2010.09.19 23:42:22 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll [2010.09.19 23:42:22 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll [2010.09.19 23:42:22 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\nvtuicpl.cpl [2010.09.19 23:42:21 | 001,474,560 | ---- | C] () -- C:\WINDOWS\System32\nview.dll [2010.09.19 23:42:21 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe [2010.09.19 23:42:21 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe [2010.09.19 23:42:21 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe [2010.09.19 23:37:41 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll [2010.09.19 23:37:19 | 000,472,576 | ---- | C] () -- C:\WINDOWS\Nvidia Omega Drivers v2.169.21 Uninstall.exe [2010.09.19 17:40:04 | 012,731,712 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Eigene Dateien\0548456956.wmv [2010.09.17 02:01:37 | 009,531,217 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Desktop\Sounds of Rain and Thunder on the River.mp3 [2010.09.15 01:44:38 | 041,137,112 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Eigene Dateien\3096964192.wmv [2010.09.15 01:31:40 | 051,761,276 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Eigene Dateien\6032963601.wmv [2010.09.13 17:48:17 | 000,130,233 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\.recently-used.xbel [2010.09.13 12:01:45 | 000,000,821 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Desktop\Britannica.lnk [2010.09.13 10:03:07 | 000,232,968 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin [2010.09.13 10:03:05 | 000,232,968 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin [2010.09.13 10:03:05 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin [2010.09.13 10:03:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvdrswr.lk [2010.09.10 21:45:37 | 000,000,572 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Desktop\Alarm.lnk [2010.09.07 20:28:29 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2010.07.19 21:35:16 | 000,004,105 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Lokale Einstellungen\Anwendungsdaten\springsettings.cfg [2010.05.23 17:34:57 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\CommonDL.dll [2010.05.23 17:34:57 | 000,002,413 | ---- | C] () -- C:\WINDOWS\System32\lgAxconfig.ini [2010.01.07 22:30:57 | 000,000,009 | ---- | C] () -- C:\WINDOWS\System32\PROTOCOL.INI [2009.12.25 15:13:10 | 000,009,506 | R--- | C] () -- C:\WINDOWS\UN070618.INI [2009.12.16 23:08:50 | 000,000,085 | ---- | C] () -- C:\WINDOWS\RealFlight.INI [2009.12.16 20:42:47 | 000,000,249 | ---- | C] () -- C:\WINDOWS\emug3.ini [2009.12.16 20:41:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI [2009.11.06 11:58:04 | 000,178,975 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat [2009.10.20 20:19:30 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll [2009.06.02 15:53:42 | 000,000,087 | ---- | C] () -- C:\WINDOWS\fs_earth_52_link_9.ini [2009.05.31 21:36:12 | 000,000,043 | ---- | C] () -- C:\WINDOWS\gswin32.ini [2009.05.27 16:56:25 | 000,000,184 | ---- | C] () -- C:\WINDOWS\hpbafd.ini [2009.05.05 18:16:51 | 000,000,024 | ---- | C] () -- C:\WINDOWS\dvzxlt.ini [2009.03.21 23:52:37 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll [2009.03.18 13:22:32 | 000,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll [2009.02.01 15:29:10 | 000,001,039 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\VodafoneConnectorService.log [2009.02.01 15:28:38 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\SendScsiCmd.dll [2009.01.16 11:21:04 | 000,000,952 | ---- | C] () -- C:\WINDOWS\uninstall_RG3.ini [2009.01.16 02:43:21 | 000,000,449 | ---- | C] () -- C:\WINDOWS\uninstall_RG1.ini [2008.12.28 17:51:12 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll [2008.11.05 00:24:01 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PDF2HTML.INI [2008.10.23 12:51:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Linden.INI [2008.10.23 12:50:51 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Linden V1.0.INI [2008.09.26 19:41:07 | 000,023,287 | ---- | C] () -- C:\WINDOWS\UN800114.INI [2008.08.14 19:56:40 | 000,000,083 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Lokale Einstellungen\Anwendungsdaten\X-Plane Installer.prf [2008.08.14 18:41:53 | 000,000,092 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Lokale Einstellungen\Anwendungsdaten\x-plane_install.txt [2008.06.27 22:50:15 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll [2008.06.19 23:00:56 | 000,181,248 | ---- | C] () -- C:\WINDOWS\System32\HPEPCEnm.dll [2008.06.11 10:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll [2008.06.11 10:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll [2008.06.11 10:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll [2008.06.11 10:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll [2008.06.11 10:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll [2008.06.11 10:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll [2008.06.11 10:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll [2008.06.11 10:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll [2008.06.11 10:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll [2008.05.01 09:38:15 | 000,000,589 | ---- | C] () -- C:\WINDOWS\smrpro.INI [2008.05.01 09:37:58 | 000,000,268 | ---- | C] () -- C:\WINDOWS\ae_mini.INI [2008.04.28 15:33:17 | 000,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys [2008.04.26 00:41:40 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI [2008.04.17 10:33:50 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\hppatusg01.dll [2008.03.09 23:22:03 | 000,000,778 | ---- | C] () -- C:\WINDOWS\joachim.ini [2008.03.04 19:52:34 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\libcurl.dll [2008.03.01 23:57:34 | 000,001,359 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\QTSBandwidthCache [2008.02.28 22:57:59 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll [2008.01.30 01:33:39 | 000,000,032 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ezsid.dat [2008.01.21 01:14:31 | 000,000,708 | ---- | C] () -- C:\WINDOWS\uninstall_Menorca.ini [2008.01.16 14:19:10 | 000,000,478 | ---- | C] () -- C:\WINDOWS\uninstall_scenery_germany_1.ini [2008.01.14 18:23:52 | 000,000,432 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI [2008.01.11 15:33:33 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI [2008.01.08 16:50:56 | 000,278,728 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys [2008.01.08 16:50:55 | 000,025,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys [2008.01.04 15:20:33 | 000,139,336 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2008.01.04 15:20:33 | 000,022,328 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Anwendungsdaten\PnkBstrK.sys [2008.01.04 15:19:53 | 000,000,308 | ---- | C] () -- C:\WINDOWS\game.ini [2007.12.23 16:32:12 | 000,002,508 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Anwendungsdaten\$_hpcst$.hpc [2007.12.23 16:30:40 | 000,000,400 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2007.11.16 20:33:35 | 000,000,042 | ---- | C] () -- C:\WINDOWS\WeatherSet.ini [2007.11.15 21:28:42 | 000,001,710 | ---- | C] () -- C:\WINDOWS\dreamcoder_mysql.INI [2007.11.15 21:26:59 | 000,061,991 | ---- | C] () -- C:\WINDOWS\uninstall_Wonderful Madeira.ini [2007.11.15 19:01:32 | 000,056,565 | ---- | C] () -- C:\WINDOWS\System32\SDL_image.dll [2007.11.14 23:25:35 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2007.11.14 23:25:33 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2007.11.14 23:25:33 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2007.11.14 23:25:32 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2007.11.14 23:25:32 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2007.11.14 23:21:19 | 000,087,040 | ---- | C] () -- C:\Dokumente und Einstellungen\HansJurg\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2007.11.14 21:16:16 | 000,000,305 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\addr_file.html [2007.11.14 19:07:37 | 000,014,658 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini [2007.11.14 19:07:23 | 000,014,620 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini [2007.11.14 19:07:23 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys [2007.11.14 19:07:16 | 000,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS [2007.10.31 10:39:54 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll [2007.05.17 14:58:10 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\libexpatw.dll [2007.03.16 17:00:00 | 000,003,403 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini [2006.09.01 19:14:08 | 000,097,280 | ---- | C] () -- C:\WINDOWS\System32\TSRemote.dll [2006.06.29 17:24:43 | 000,318,014 | ---- | C] () -- C:\WINDOWS\System32\flt1chk4.dll [2005.01.15 00:51:21 | 000,000,151 | ---- | C] () -- C:\WINDOWS\swfl5.ini [2004.10.28 17:38:10 | 000,315,728 | ---- | C] () -- C:\WINDOWS\System32\flt1chk3.dll [2003.05.30 17:27:46 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\CmCardRm.dll [2002.02.27 18:50:00 | 000,197,120 | ---- | C] () -- C:\WINDOWS\System32\patchw32.dll [2001.07.31 04:17:12 | 000,094,274 | ---- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL ========== Alternate Data Streams ========== @Alternate Data Stream - 233 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:D282699C @Alternate Data Stream - 143 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:4A29ED9D @Alternate Data Stream - 104 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:B7CB7C6C < End of report > Und die Extras.txt: OTL EXTRAS Logfile: OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 24.09.2010 09:45:54 - Run 1 OTL by OldTimer - Version 3.2.14.1 Folder = C:\Dokumente und Einstellungen\HansJurg\Desktop Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 71,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 83,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 465,75 Gb Total Space | 375,91 Gb Free Space | 80,71% Space Free | Partition Type: NTFS D: Drive not present or media not loaded Drive E: | 465,76 Gb Total Space | 333,49 Gb Free Space | 71,60% Space Free | Partition Type: NTFS Drive F: | 931,51 Gb Total Space | 379,19 Gb Free Space | 40,71% Space Free | Partition Type: NTFS G: Drive not present or media not loaded Drive H: | 1014,88 Mb Total Space | 42,39 Mb Free Space | 4,18% Space Free | Partition Type: FAT32 I: Drive not present or media not loaded Computer Name: CHOCHMAH Current User Name: HansJurg Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html [@ = Opera.HTML] -- C:\Programme\Opera\Opera.exe (Opera Software) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. http [open] -- "C:\Programme\Opera\opera.exe" (Opera Software) https [open] -- "C:\Programme\Opera\Opera.exe" (Opera Software) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002 "26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 "26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service "8118:TCP" = 8118:TCP:*:Enabled:maskip "22681:TCP" = 22681:TCP:*:Enabled:qip "5900:TCP" = 5900:TCP:*:Enabled:vnc5900 "5800:TCP" = 5800:TCP:*:Enabled:vnc5800 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\Programme\Microsoft ActiveSync\rapimgr.exe" = C:\Programme\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager -- (Microsoft Corporation) "C:\Programme\Microsoft ActiveSync\wcescomm.exe" = C:\Programme\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager -- (Microsoft Corporation) "C:\Programme\Microsoft ActiveSync\WCESMgr.exe" = C:\Programme\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application -- (Microsoft Corporation) "C:\Programme\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe" = C:\Programme\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe:*:Enabled:HP Easy Printer Care HPPRun -- (Hewlett-Packard Company) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "E:\games\fs9\fs9.exe" = E:\games\fs9\fs9.exe:*:Enabled:Microsoft Flight Simulator -- File not found "C:\WINDOWS\system32\dpnsvr.exe" = C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server -- (Microsoft Corporation) "C:\Programme\Opera\Opera.exe" = C:\Programme\Opera\Opera.exe:*:Enabled:Opera Internet Browser -- (Opera Software) "C:\Programme\eMule\emule.exe" = C:\Programme\eMule\emule.exe:*:Enabled:eMule -- (hxxp://www.emule-project.net) "C:\Programme\Azureus\Azureus.exe" = C:\Programme\Azureus\Azureus.exe:*:Enabled:Azureus -- (Vuze Inc.) "C:\Programme\Zone Five Software\SportTracks 2.0\SportTracks.exe" = C:\Programme\Zone Five Software\SportTracks 2.0\SportTracks.exe:*:Enabled:SportTracks -- (ZoneFiveSoftware) "C:\Programme\Microsoft ActiveSync\rapimgr.exe" = C:\Programme\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager -- (Microsoft Corporation) "C:\Programme\Microsoft ActiveSync\wcescomm.exe" = C:\Programme\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager -- (Microsoft Corporation) "C:\Programme\Microsoft ActiveSync\WCESMgr.exe" = C:\Programme\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application -- (Microsoft Corporation) "C:\Programme\id Software\Enemy Territory - QUAKE Wars\etqwded.exe" = C:\Programme\id Software\Enemy Territory - QUAKE Wars\etqwded.exe:*:Enabled:etqwded.exe -- (Splash Damage, Ltd.) "C:\Programme\id Software\Enemy Territory - QUAKE Wars\etqw.exe" = C:\Programme\id Software\Enemy Territory - QUAKE Wars\etqw.exe:*:Enabled:Enemy Territory - QUAKE Wars(TM) -- (Splash Damage, Ltd.) "C:\Programme\mIRC\mirc.exe" = C:\Programme\mIRC\mirc.exe:*:Enabled:mIRC -- (mIRC Co. Ltd.) "E:\games\Supreme Ruler 2010\SupremeRuler.exe" = E:\games\Supreme Ruler 2010\SupremeRuler.exe:*:Enabled:Supreme Ruler 2010 -- (BattleGoat Studios) "E:\games\X-Plane 9-Demo\X-Plane.exe" = E:\games\X-Plane 9-Demo\X-Plane.exe:*:Enabled:X-Plane -- () "C:\Dokumente und Einstellungen\HansJurg\Anwendungsdaten\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Dokumente und Einstellungen\HansJurg\Anwendungsdaten\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player -- (Octoshape ApS) "C:\Programme\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Programme\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation) "C:\Programme\fotobuch.de AG\Designer 2.0\Designer.exe" = C:\Programme\fotobuch.de AG\Designer 2.0\Designer.exe:*:Designer.exe -- () "C:\Programme\Miranda IM\miranda32.exe" = C:\Programme\Miranda IM\miranda32.exe:*:Enabled:Miranda IM -- ( ) "C:\Programme\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe" = C:\Programme\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe:*:Enabled:HP Easy Printer Care HPPRun -- (Hewlett-Packard Company) "C:\WINDOWS\system32\javaw.exe" = C:\WINDOWS\system32\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.) "E:\games\fs9\widefs\WideClient.exe" = E:\games\fs9\widefs\WideClient.exe:*:Enabled:FS Eliminator for FSUIPC client applications -- File not found "C:\Programme\FSFDT\Control Panel\FSFDTCP.exe" = C:\Programme\FSFDT\Control Panel\FSFDTCP.exe:*:Enabled:FSFDT Control Panel -- File not found "C:\Programme\FSFDT\FWInn\FWINN.exe" = C:\Programme\FSFDT\FWInn\FWINN.exe:*:Enabled:FSInn Application -- File not found "C:\Programme\Codemasters\GRID\GRID.exe" = C:\Programme\Codemasters\GRID\GRID.exe:*:Enabled:GRID -- (Codemasters) "C:\Programme\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" = C:\Programme\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Enabled:Veoh Web Player -- File not found "C:\Programme\uTorrent\uTorrent.exe" = C:\Programme\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.) "E:\games\dirt2\dirt2_game.exe" = E:\games\dirt2\dirt2_game.exe:*:Enabled:DiRT2 -- (Codemasters) "C:\Programme\LANMailServer\lanmailserver.exe" = C:\Programme\LANMailServer\lanmailserver.exe:*:Enabled:LANMailServer -- File not found "C:\Dokumente und Einstellungen\HansJurg\Lokale Einstellungen\Temp\Rar$EX00.797\MyFsGoogleEarth-1-0-1\MyFsGoogleEarth.exe" = C:\Dokumente und Einstellungen\HansJurg\Lokale Einstellungen\Temp\Rar$EX00.797\MyFsGoogleEarth-1-0-1\MyFsGoogleEarth.exe:*:Enabled:MyFsGoogleEarth -- File not found "C:\Dokumente und Einstellungen\HansJurg\Lokale Einstellungen\Anwendungsdaten\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Dokumente und Einstellungen\HansJurg\Lokale Einstellungen\Anwendungsdaten\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin -- File not found "C:\Dokumente und Einstellungen\HansJurg\Anwendungsdaten\Dropbox\bin\Dropbox.exe" = C:\Dokumente und Einstellungen\HansJurg\Anwendungsdaten\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox -- () "C:\Programme\SopCast\adv\SopAdver.exe" = C:\Programme\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver -- (www.sopcast.com) "C:\Programme\SopCast\SopCast.exe" = C:\Programme\SopCast\SopCast.exe:*:Enabled:SopCast Main Application -- (www.sopcast.com) "E:\games\fsx\fsx.exe" = E:\games\fsx\fsx.exe:*:Enabled:Microsoft Flight Simulator® -- (Microsoft Corp.) "E:\games\fsx\FSFDT\FWInn\FWINN.exe" = E:\games\fsx\FSFDT\FWInn\FWINN.exe:*:Enabled:FSInn Application -- () "E:\games\fsx\FSFDT\Control Panel\FSFDTCP.exe" = E:\games\fsx\FSFDT\Control Panel\FSFDTCP.exe:*:Enabled:FSFDT Control Panel -- (FS - French Dev Team) "E:\games\CC-TB\Data\CNC4.game" = E:\games\CC-TB\Data\CNC4.game:*:Disabled:Command & Conquer™ 4 -- File not found "E:\games\Spring\springlobby.exe" = E:\games\Spring\springlobby.exe:*:Enabled:springlobby -- File not found "E:\games\Spring\spring.exe" = E:\games\Spring\spring.exe:*:Enabled:spring -- File not found "E:\games\spring+\springlobby.exe" = E:\games\spring+\springlobby.exe:*:Enabled:springlobby -- () "E:\games\spring+\spring.exe" = E:\games\spring+\spring.exe:*:Enabled:spring -- () "E:\games\traackmania\TmForever.exe" = E:\games\traackmania\TmForever.exe:*:Enabled:TmForever -- File not found "C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Disabled:Windows Explorer -- (Microsoft Corporation) "C:\Programme\MATLAB\R2009b\bin\win32\MATLAB.exe" = C:\Programme\MATLAB\R2009b\bin\win32\MATLAB.exe:*:Disabled:MATLAB -- (The MathWorks Inc.) "C:\Programme\UltraVNC\winvnc.exe" = C:\Programme\UltraVNC\winvnc.exe:*:Enabled:winvnc.exe -- (UltraVNC) "C:\Programme\UltraVNC\vncviewer.exe" = C:\Programme\UltraVNC\vncviewer.exe:*:Enabled:vncviewer.exe -- (UltraVNC) "E:\games\StarCraft II\StarCraft II.exe" = E:\games\StarCraft II\StarCraft II.exe:*:Enabled:Blizzard Launcher -- File not found "E:\games\StarCraft II\Versions\Base15405\SC2.exe" = E:\games\StarCraft II\Versions\Base15405\SC2.exe:*:Enabled:StarCraft II -- File not found "C:\Programme\Google\Google Earth\client\googleearth.exe" = C:\Programme\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth -- (Google) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{01339AE5-04D4-43F8-008E-13AD788DC4F7}" = SimCity 4 "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{07CC448E-4FFC-444F-999D-10F11AE559FB}" = aerosoft's - Mallorca X for FSX "{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}" = Search Settings 1.2.1 "{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in "{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter "{15F4085A-BC98-4590-AFFD-03BBBE49524E}" = Garmin Communicator Plugin "{17440258-DB48-49DE-8391-79900477490C}" = aerosoft's - Madeira X "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate "{18E65799-76BD-46EF-9E53-972FE5A40736}" = Opera 10.62 "{1B14B0C3-2D60-477C-A1FE-B88E60948854}" = OpenOffice.org 2.4 "{1E8EF6C8-1DC7-4DEA-A776-4EDF78B9654B}" = Microsoft Network Monitor: Microsoft Parsers 3.3 "{1F698102-5739-441E-96F0-74F4EA540F06}" = Attansic Ethernet Utility "{25BD12B0-0FD4-11D4-B2A8-005004806F3E}" = Maple 6 "{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 19 "{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (HPWJA) "{2BEB102E-F9CD-4881-984B-E288F66FD394}" = Quake Live Mozilla Plugin "{31A57C3E-30DD-421F-B5C7-974DACB0D05F}" = Canon Camera WIA Driver "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3 "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5 "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7 "{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker "{409ECFF1-9CC7-43A8-B28A-B7F0B7CB04D1}_is1" = Classic Menu 3.9x for Office 2007 "{428102E6-8A39-48B9-8389-847F5A44A600}" = MSXML 4.0 "{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth "{48E80C20-00B3-11D4-AA4A-00C0580802FD}" = USB Picture Card Reader "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4CFCC6FD-AEA2-4208-99A6-45CBF9DFFD82}" = Real Environment Xtreme "{52D1D62C-FEAB-4580-849E-1DB624BADBBD}" = DiRT2 "{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English) "{548CC5A0-F2E2-11DD-6172-0DC7E1C11916}" = Vopt 9 "{54BB0384-1C33-488F-A95B-877E480D3EDC}" = MSXML 4.0 "{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer "{5A0B7BA5-4682-4273-81C2-69B17E649103}" = GRID "{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{70C4EFA5-F8B8-4015-9378-FCAA9000DF19}" = MotionBased Agent "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser und SDK "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762 "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec "{8A809006-C25A-4A3A-9DAB-94659BCDB107}" = NVIDIA PhysX "{8AA037A8-E104-493A-A962-8D58535A0198}" = MySQL Server 5.0 "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player "{8C5FAD77-F678-4758-A296-C12F08D179E0}" = Microsoft IntelliPoint 6.2 "{90120000-0010-0407-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (German) 12 "{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007 "{90120000-0015-0407-0000-0000000FF1CE}_PROPLUSR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0016-0407-0000-0000000FF1CE}_PROPLUSR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}_PROPLUSR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007 "{90120000-0019-0407-0000-0000000FF1CE}_PROPLUSR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007 "{90120000-001A-0407-0000-0000000FF1CE}_PROPLUSR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}_PROPLUSR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_PROPLUSR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_PROPLUSR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_PROPLUSR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-001F-0410-0000-0000000FF1CE}_PROPLUSR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007 "{90120000-0044-0407-0000-0000000FF1CE}_PROPLUSR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}_PROPLUSR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2) "{907B3A12-1392-4BCF-A0B5-49AAC2E2EA5D}" = LECTURNITY Player "{91120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007 "{91120000-0011-0000-0000-0000000FF1CE}_PROPLUSR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-0011-0000-0000-0000000FF1CE}_PROPLUSR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{9195706A-CEB6-4B88-85CE-D3BEB19F11C4}" = Microsoft Network Monitor 3.3 "{93E61AF4-29C4-11D9-A9CC-0080AD30B67D}" = Landscape Germany Mesh "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3 "{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT (x86) WinSXS MSM "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A06A6679-41D7-48C5-82F8-7D3B0B654720}" = Active Sky X "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A47FC79E-FEC9-4E55-8317-538E8D3647F8}" = X Graphics "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A901BF63-29AD-49A3-B067-231925E98B62}_is1" = Version 1.0 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support "{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder "{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter "{ABE8B5D0-4B4A-4D45-8A33-6721C29F963F}" = ClearView "{AC76BA86-7AD7-1031-7B44-A82000000003}" = Adobe Reader 8.2.4 - Deutsch "{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder "{AF7362B6-BD39-4848-A991-3BA4319444AC}" = Landscape Germany Landclass "{B1102A25-3AA3-446B-AA0F-A699B07A02FD}" = Garmin USB Drivers "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter "{B208806F-A231-4FA0-AB3F-5C1B8979223E}" = Microsoft ActiveSync 4.0 "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player "{B7A585C8-CE4E-4150-84C6-A13C3CB1379F}" = Enemy Territory - Quake Wars(TM) "{B9242864-2841-4ADE-86E0-8F90F91B04DD}" = Logitech Gaming Software "{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation "{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU "{C309F22B-19ED-4667-950C-2188A4B26E34}" = Google SketchUp Pro 7 "{C314CE45-3392-3B73-B4E1-139CD41CA933}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU "{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D066C0E0-A915-11D5-B078-00C0F6A04C3E}" = "{D5842AC3-59C7-4DDD-BB33-54FE544DB3DA}" = Komponenten der Betriebssystemkommunikation "{DA46AA5F-4934-4DAC-94E4-7D84AD9A4090}" = Project Canarias 2006 "{DE659AC8-EEF0-4115-AA0C-6500D194FB10}" = Garmin Training Center v4 "{E6FA148F-1E7D-4A42-A9A2-7DFABC2C6A2B}" = SportTracks 2.1 "{e7394a0f-3f80-45b1-87fc-abcd51893246}" = Python 2.6.4 "{E7CC4B85-DC2F-463F-8FEB-E7398E25C19A}" = Microsoft Flight Simulator X Service Pack 2 "{EA6E7823-9E5B-4EDD-9750-C3C87FDF0460}" = aerosoft's - German Airports 3 - Hamburg X "{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F5345C76-AC35-4EDA-8406-1346DE9BFDFA}" = Graphviz "{F535B2CF-C9BB-4162-B03A-02D6971F32CC}" = Microsoft Flight Simulator X "{F69FD33C-8815-46BF-9134-A643DE68F3C0}" = WinFast(R) Display Driver "{F7B0E599-C114-4493-BC4D-D8FC7CBBABBB}" = 32 Bit HP CIO Components Installer "{FA237125-51FF-408C-8BB8-30C2B3DFFF9C}" = Windows Resource Kit Tools "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0) "678B5665-C9E7-4853-91C9-05A2FD16B179_is1" = Registry CleanUP 2007 "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe SVG Viewer" = Adobe SVG Viewer 3.0 "Advanced Strategic Command" = Advanced Strategic Command "Airbus Series Vol.1 (FS X)" = Airbus Series Vol.1 (FS X) "Alarm_is1" = Alarm 2.0.1 "Arasan_is1" = Arasan 10.3 "Aspell" = Aspell Data "Aspell English Dictionary_is1" = Aspell English Dictionary-0.50-2 "Aspell German Dictionary_is1" = Aspell German Dictionary-0.50-2 "Aspell6-Dictionary-de" = Aspell 0.6 Dictionary (Language: de) "Aspell6-Dictionary-en" = Aspell 0.6 Dictionary (Language: en) "AutoHotkey" = AutoHotkey 1.0.47.06 "Autopano Pro" = Autopano Pro "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "AVMWLANCLI" = AVM FRITZ!WLAN "Azureus" = Azureus "Blender" = Blender (remove only) "C-Media Card Reader Driver" = C-Media USB Mass Storage Driver "Combined Community Codec Pack_is1" = Combined Community Codec Pack 2009-09-09 "Deep Exploration" = Deep Exploration "Designer 2.0_is1" = Designer 2.0 "Dev-C++" = Dev-C++ 5 beta 9 release (4.9.9.2) "Dia" = Dia (nur entfernen) "DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters "DreamCoder for MySQL Free Edition_is1" = DreamCoder for MySQL 4.2 "EasyBCD" = EasyBCD 1.7.2 "eMule" = eMule "Encyclopaedia Britannica 2006 Ultimate Reference Suite DVD" = Encyclopaedia Britannica 2006 Ultimate Reference Suite DVD "FileZilla Client" = FileZilla Client 3.3.3 "FSFDT FSCopilot" = FSFDT FSCopilot "FSFDT FSInn" = FSFDT FSInn "GNU Aspell_is1" = GNU Aspell 0.50-3 "GPL Ghostscript 8.61" = GPL Ghostscript 8.61 "GPL Ghostscript Fonts" = GPL Ghostscript Fonts "GPS-Track-Analyse.NET" = GPS-Track-Analyse.NET "Grep-2.5.4_is1" = GnuWin32: Grep-2.5.4 "GSview 4.9" = GSview 4.9 "GTK 2.0" = GTK+ Runtime 2.12.8 rev a (nur entfernen) "HiSerial.sys Serial Port Driver" = HiSerial.sys Serial Port Driver "ImageMagick 6.3.7 Q16_is1" = ImageMagick 6.3.7-8 Q16 (01/01/08) "imgThumb_is1" = imgThumb 1.5.4 "InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in "InstallShield_{31A57C3E-30DD-421F-B5C7-974DACB0D05F}" = Canon EOS Kiss REBEL 300D WIA-Treiber "InstallShield_{B7B6C0BE-C919-425C-A493-DF9FF11249F5}" = Enemy Territory - QUAKE Wars(TM) Demo 1.1 Patch "InstallShield_{F535B2CF-C9BB-4162-B03A-02D6971F32CC}" = Microsoft Flight Simulator X "IrfanView" = IrfanView (remove only) "King Arthur_is1" = King Arthur "KLiteCodecPack_is1" = K-Lite Mega Codec Pack 1.49 "LastFM_is1" = Last.fm 1.5.4.24567 "LFRD2004 St-Malo Dinard Pleurtuit" = LFRD2004 St-Malo Dinard Pleurtuit "LyX" = LyX 1.6.4-1 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "MatlabR2009b" = MATLAB R2009b "Mediacenter 1.0 Coolstreaming_is1" = Mediacenter 1.0 "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft SQL Server 2005" = Microsoft SQL Server 2005 "MiKTeX 2.7" = MiKTeX 2.7 "Miranda IM" = Miranda IM 0.9.2 "mIRC" = mIRC "Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8) "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "Multi Clipboard" = Multi Clipboard "NVIDIA Display Control Panel" = NVIDIA Display Control Panel "NVIDIA Drivers" = NVIDIA Drivers "NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager "Nvidia Omega Drivers for Windows XP/2kv2.169.21" = Nvidia Omega Drivers v2.169.21 Setup Files "OpenAL" = OpenAL "Picasa 3" = Picasa 3 "POV-Ray for Windows v3.6" = POV-Ray for Windows v3.6.1c "Project Canarias 2006" = "PROPLUSR" = Microsoft Office Professional Plus 2007 "Psion CD Installer" = Psion CD Installer "PsiWin 2.3" = PsiWin 2.3 "PunkBusterSvc" = PunkBuster Services "RealFlightG4Pro" = RealFlight G4 R/C Simulator "ScriptFTP" = ScriptFTP "SopCast" = SopCast 3.2.9 "Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.4 "SP1_F535B2CF-C9BB-4162-B03A-02D6971F32CC" = Microsoft Flight Simulator X Service Pack 1 "Spring" = Spring 0.81.2.1 "Spring - Test Build" = Spring - Test Build 0.81.2.1-1377-ge7e87ab "ST6UNST #1" = WidevieW 2004 "Stellarium_is1" = Stellarium 0.10.4 "Streamripper" = Streamripper (Remove only) "SystemRequirementsLab" = System Requirements Lab "TCPMP" = TCPMP "Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2 "TellmeMoreV50" = TeLL me More "tento" = tento "TeXnicCenter_is1" = TeXnicCenter Version 1 Beta 7.01 (Greengrass) "The Rosetta Stone" = The Rosetta Stone "Torrent Episode Downloader 0.96" = Torrent Episode Downloader "Torrent Episode Downloader 0.971" = Torrent Episode Downloader "Total Image Slicer_is1" = ImageSlicer "Tweak UI 2.10" = Tweak UI "UFRaw_is1" = UFRaw 0.13 "Ultimate++" = Ultimate++ "Ultravnc2_is1" = UltraVNC 1.0.8.2 "UN070618" = BUFFALO TurboUSB for FLASH/HDD "uTorrent" = µTorrent "vasFMC_is1" = vasFMC 1.10 "VATSpy" = VAT-Spy "VirtuaWin_is1" = VirtuaWin v4.0.1 "VLC media player" = VideoLAN VLC media player 0.8.4a "Volga-Dnepr. IL-76 screensaver_is1" = Volga-Dnepr. IL-76 screensaver 1.0 "Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 "Winamp" = Winamp "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinEdt_is1" = WinEdt "WinGimp-2.0_is1" = GIMP 2.4.2 "WinPcapInst" = WinPcap 4.1.1 "WinRAR archiver" = WinRAR "Wireshark" = Wireshark 1.2.6 "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "XpsEPSC" = XML Paper Specification Shared Components Pack 1.0 "XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0 ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "171a3bd25b2ddd36" = vroute.info "Dropbox" = Dropbox "FeelThere E-Jets v.2" = FeelThere E-Jets v.2 "FsxAdventures EasyJet Missions Vol 1. v1.0" = FsxAdventures EasyJet Missions Vol 1. v1.0 "Gambit" = Gambit "Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player "Ultimate Terrain X - Europe" = Ultimate Terrain X - Europe "Winamp Detect" = Winamp Erkennungs-Plug-in ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 23.09.2010 22:30:05 | Computer Name = CHOCHMAH | Source = Google Update | ID = 20 Description = Error - 23.09.2010 23:30:05 | Computer Name = CHOCHMAH | Source = Google Update | ID = 20 Description = Error - 24.09.2010 00:30:05 | Computer Name = CHOCHMAH | Source = Google Update | ID = 20 Description = Error - 24.09.2010 00:44:47 | Computer Name = CHOCHMAH | Source = Application Error | ID = 1000 Description = Fehlgeschlagene Anwendung mbam.exe, Version 1.46.0.0, fehlgeschlagenes Modul unknown, Version 0.0.0.0, Fehleradresse 0x0014537f. Error - 24.09.2010 00:44:57 | Computer Name = CHOCHMAH | Source = Application Error | ID = 1000 Description = Fehlgeschlagene Anwendung j2.exe, Version 0.0.0.0, fehlgeschlagenes Modul unknown, Version 0.0.0.0, Fehleradresse 0x0014537f. Error - 24.09.2010 00:45:47 | Computer Name = CHOCHMAH | Source = Application Error | ID = 1000 Description = Fehlgeschlagene Anwendung j2.exe, Version 0.0.0.0, fehlgeschlagenes Modul unknown, Version 0.0.0.0, Fehleradresse 0x0014537f. Error - 24.09.2010 00:46:40 | Computer Name = CHOCHMAH | Source = Application Error | ID = 1000 Description = Fehlgeschlagene Anwendung notepad.exe, Version 5.1.2600.5512, fehlgeschlagenes Modul unknown, Version 0.0.0.0, Fehleradresse 0x0009537f. Error - 24.09.2010 01:30:05 | Computer Name = CHOCHMAH | Source = Google Update | ID = 20 Description = Error - 24.09.2010 02:30:05 | Computer Name = CHOCHMAH | Source = Google Update | ID = 20 Description = Error - 24.09.2010 03:30:05 | Computer Name = CHOCHMAH | Source = Google Update | ID = 20 Description = [ OSession Events ] Error - 07.10.2009 08:22:09 | Computer Name = CHOCHMAH | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 3450 seconds with 0 seconds of active time. This session ended with a crash. [ System Events ] Error - 23.09.2010 18:47:28 | Computer Name = CHOCHMAH | Source = NetBT | ID = 4321 Description = Der Name "MIDGARD :1d" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.0.9 registriert werden. Der Computer mit IP-Adresse 192.168.0.6 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error - 23.09.2010 18:52:38 | Computer Name = CHOCHMAH | Source = NetBT | ID = 4321 Description = Der Name "MIDGARD :1d" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.0.9 registriert werden. Der Computer mit IP-Adresse 192.168.0.6 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error - 23.09.2010 18:57:48 | Computer Name = CHOCHMAH | Source = NetBT | ID = 4321 Description = Der Name "MIDGARD :1d" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.0.9 registriert werden. Der Computer mit IP-Adresse 192.168.0.6 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error - 23.09.2010 19:00:30 | Computer Name = CHOCHMAH | Source = Service Control Manager | ID = 7000 Description = Der Dienst "HPWJA Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%3 Error - 23.09.2010 19:00:30 | Computer Name = CHOCHMAH | Source = Service Control Manager | ID = 7000 Description = Der Dienst "nHancer Support" wurde aufgrund folgenden Fehlers nicht gestartet: %%3 Error - 23.09.2010 19:00:33 | Computer Name = CHOCHMAH | Source = sptd | ID = 262148 Description = Der Treiber hat einen internen Fehler in seinen Datenstrukturen für festgestellt. Error - 23.09.2010 19:01:05 | Computer Name = CHOCHMAH | Source = NetBT | ID = 4321 Description = Der Name "MIDGARD :1d" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.0.9 registriert werden. Der Computer mit IP-Adresse 192.168.0.6 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error - 23.09.2010 19:01:50 | Computer Name = CHOCHMAH | Source = Service Control Manager | ID = 7034 Description = Dienst "HP WJA Update Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error - 23.09.2010 19:02:52 | Computer Name = CHOCHMAH | Source = NetBT | ID = 4321 Description = Der Name "MIDGARD :1d" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.0.9 registriert werden. Der Computer mit IP-Adresse 192.168.0.6 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error - 23.09.2010 19:08:02 | Computer Name = CHOCHMAH | Source = NetBT | ID = 4321 Description = Der Name "MIDGARD :1d" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.0.9 registriert werden. Der Computer mit IP-Adresse 192.168.0.6 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. < End of report > Ich glaube ich konnte das Problem durch kopieren der Lösung aus dem Forum beheben. |
Themen zu Programme beenden mit Error |
0x00000001, 32 bit, acroiehelper.dll, adobe, alternate, antivir, avgntflt.sys, avira, bho, buffalo, components, einstellungen, error, excel.exe, explorer, extras.txt, firefox, format, google earth, home, homepage, internet, internet browser, ip-adresse, location, logfile, microsoft office word, mozilla, nodrives, notepad.exe, nvidia, object, oldtimer, opera.exe, otl.exe, pdf, picasa, plug-in, problem, programme, realtek, registry, saver, sched.exe, searchplugins, security update, server, shell32.dll, sketchup, software, sophos anti-rootkit, sptd.sys, stick, system restore, temp, vlc media player |